10 thoughts on “Easier managing account management modes for Windows LAPS”

  1. Peter, once again you’ve delivered an exceptionally clear and thorough article. Every time there’s an important Intune feature that needs proper attention, you’re the person I rely on to get it configured right. This post about managing account management modes for Windows LAPS is no exception — the way you break down the complexity and provide real-world configuration guidance is invaluable.

    Your explanations are always solid, practical, and straight to the point. Thank you for continuing to share your knowledge so generously with the rest of us!

    Reply
  2. I have a problem. I have configured LAPS policy but i’ts not aplied with a cusom account name because all lapstops, when enrolled, are Windows 11 23H2. The policy will change the password for default administrator account but won’t enable it.

    When laptops update to Windows 11 24H2, 80 % of the laptops does not have the custon admin account. I don’t know when the policy will reapply and create the custom admin account.

    Reply
      • I have only one policy. On 23H2 laptops the policy will change the password for Windows bulit-in administrator account but does not enable it. On 24H2 laptops the policy will create the custom myadmin account, enable it and change the password.

        LAPS POLICY in Intune > Endpoint security > Account protection
        Backup Directory: Backup the password to Microsoft Entra ID only
        Password Age Days: 180
        Password Complexity: Large letters + small letters + numbers
        Password Length: 12
        Post Authentication Reset Delay: 24
        Automatic Account Management Enabled: The target account will be automatically managed
        Automatic Account Management Randomize Name: The name of the target account will not use a random numeric suffix.
        Automatic Account Management Name Or Prefix: myadmin
        Automatic Account Management Enable Account: The target account will be enabled
        Automatic Account Management Target: Manage a new custom administrator account

        About 80 laptops was enrolled when those were on version 23H2. Now those have updated to 24H2 but for most of the laptops Intune shows that the LAPS account is Administrator and I cannot log in with this accoubnt because it’s not enabled. Some laptops show myadmin account and login works.

        Now I have one laptop on my desktop and could not login because there was no myadmin account. I pressed Rotate Local Admin Password in Intune for that device -> myadmin account was created and the account and password is shown in Intune. Maybe I should set the password age to eg. 7 days to make this happen automatically and sooner than 180 days which is now configured. The laptops which have myadmin account were enrolled about three months ago so the account was updated sooner than 180 days.

        I considered using the built-in administrator account and enabling it by an additional policy but couldn’t figure out how to make sure that the account is enabled only after the LAPS policy has changed the password.

        Reply
        • So, basically, the policy is not reapplied when upgrading from 23H2 to 24H2, and the policy keeps the same successful status. The only thing I could think of is to trigger an update by making an adjustment to the policy…
          Regards, Peter

          Reply
  3. Hello Peter,

    Can you see the account name under the device -> local admin password if you enable the automatic account management and randomize the account name?

    Thank you for your invaluable blog!

    Reply
    • Hi Michaël,
      You need to enable the Entra setting (Enable Local Administrator Password Solution (LAPS)) first and make sure that you are storing the information in Entra. After that, the answer is yes.
      Regards, Peter

      Reply
      • Thank you Peter, I’ve used LAPS before but only for generating a password. I was curious whether it would show the randomly generated admin account as well. Thanks!

        Reply

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.